RHSA-2020:2840HighCVSS 7.6
Red Hat Security Advisory: tomcat security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2020-1938 — tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability
🎯 Affected products51
- Red Hat Enterprise Linux ComputeNode EUS (v. 7.6)
- Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.6)
- Red Hat Enterprise Linux Server EUS (v. 7.6)
- Red Hat Enterprise Linux Server Optional EUS (v. 7.6)
- Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7)
- Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7)
- tomcat-0:7.0.76-10.el7_6.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.6)
- tomcat-0:7.0.76-10.el7_6.noarch as a component of Red Hat Enterprise Linux Server EUS (v. 7.6)
- tomcat-0:7.0.76-10.el7_6.noarch as a component of Red Hat Enterprise Linux Server Optional EUS (v. 7.6)
- tomcat-0:7.0.76-10.el7_6.noarch as a component of Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7)
- tomcat-0:7.0.76-10.el7_6.noarch as a component of Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7)
- tomcat-0:7.0.76-10.el7_6.src as a component of Red Hat Enterprise Linux ComputeNode EUS (v. 7.6)
- tomcat-0:7.0.76-10.el7_6.src as a component of Red Hat Enterprise Linux Server EUS (v. 7.6)
- tomcat-0:7.0.76-10.el7_6.src as a component of Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7)
- tomcat-admin-webapps-0:7.0.76-10.el7_6.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.6)
- tomcat-admin-webapps-0:7.0.76-10.el7_6.noarch as a component of Red Hat Enterprise Linux Server EUS (v. 7.6)
- tomcat-admin-webapps-0:7.0.76-10.el7_6.noarch as a component of Red Hat Enterprise Linux Server Optional EUS (v. 7.6)
- tomcat-admin-webapps-0:7.0.76-10.el7_6.noarch as a component of Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7)
- tomcat-admin-webapps-0:7.0.76-10.el7_6.noarch as a component of Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7)
- tomcat-docs-webapp-0:7.0.76-10.el7_6.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.6)
- tomcat-docs-webapp-0:7.0.76-10.el7_6.noarch as a component of Red Hat Enterprise Linux Server Optional EUS (v. 7.6)
- tomcat-docs-webapp-0:7.0.76-10.el7_6.noarch as a component of Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7)
- tomcat-el-2.2-api-0:7.0.76-10.el7_6.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.6)
- tomcat-el-2.2-api-0:7.0.76-10.el7_6.noarch as a component of Red Hat Enterprise Linux Server EUS (v. 7.6)
- tomcat-el-2.2-api-0:7.0.76-10.el7_6.noarch as a component of Red Hat Enterprise Linux Server Optional EUS (v. 7.6)
- tomcat-el-2.2-api-0:7.0.76-10.el7_6.noarch as a component of Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7)
- tomcat-el-2.2-api-0:7.0.76-10.el7_6.noarch as a component of Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7)
- tomcat-javadoc-0:7.0.76-10.el7_6.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.6)
- tomcat-javadoc-0:7.0.76-10.el7_6.noarch as a component of Red Hat Enterprise Linux Server Optional EUS (v. 7.6)
- tomcat-javadoc-0:7.0.76-10.el7_6.noarch as a component of Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7)
- +21 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Please refer to the Red Hat knowledgebase article: https://access.redhat.com/solutions/4851251